Early Detection Of Mirai-Like IoT Bots In Large-Scale Networks Through Sub-Sampled Packet Traffic Analysis

01/15/2019
by   Ayush Kumar, et al.
0

The widespread adoption of Internet of Things has led to many security issues. Recently, there have been malware attacks on IoT devices, the most prominent one being that of Mirai. IoT devices such as IP cameras, DVRs and routers were compromised by the Mirai malware and later large-scale DDoS attacks were propagated using those infected devices (bots) in October 2016. In this research, we develop a network-based algorithm which can be used to detect IoT bots infected by Mirai or similar malware in large-scale networks (e.g. ISP network). The algorithm particularly targets bots scanning the network for vulnerable devices since the typical scanning phase for botnets lasts for months and the bots can be detected much before they are involved in an actual attack. We analyze the unique signatures of the Mirai malware to identify its presence in an IoT device. Further, to optimize the usage of computational resources, we use a two-dimensional (2D) packet sampling approach, wherein we sample the packets transmitted by IoT devices both across time and across the devices. Leveraging the Mirai signatures identified and the 2D packet sampling approach, a bot detection algorithm is proposed. We use testbed measurements and simulations to study the relationship between bot detection delays and the sampling frequencies for device packets. Subsequently, we derive insights from the obtained results and use them to design our proposed bot detection algorithm. Finally, we discuss the deployment of our bot detection algorithm and the countermeasures which can be taken post detection.

READ FULL TEXT

page 1

page 2

page 3

page 4

research
06/24/2019

EDIMA: Early Detection of IoT Malware Network Activity Using Machine Learning Techniques

The widespread adoption of Internet of Things has led to many security i...
research
05/30/2021

IoTAthena: Unveiling IoT Device Activities from Network Traffic

The recent spate of cyber attacks towards Internet of Things (IoT) devic...
research
06/17/2019

A Secure Contained Testbed for Analyzing IoT Botnets

Many security issues have come to the fore with the increasingly widespr...
research
04/20/2018

DÏoT: A Crowdsourced Self-learning Approach for Detecting Compromised IoT Devices

IoT devices are being widely deployed. Many of them are vulnerable due t...
research
07/08/2020

Graph Neural Networks-based Clustering for Social Internet of Things

In this paper, we propose a machine learning process for clustering larg...
research
10/21/2021

Classification of Encrypted IoT Traffic Despite Padding and Shaping

It is well known that when IoT traffic is unencrypted it is possible to ...
research
05/05/2021

Current State of IPv6 Security in IoT

This report presents the current state of security in IPv6 for IoT devic...

Please sign up or login with your details

Forgot password? Click here to reset